The case, explained

Civil Liability for Man-in-the-Middle Scams in Corporate Payments

7 min read · Updated September 2026 · Editorial oversight: Avv. Federico Papa

Recent jurisprudential developments mark a turning point in managing cyber risk for businesses and credit institutions. According to reports in the specialized press, the debate has focused on the distribution of damages resulting from so-called Man-in-the-Middle (MITM) scams, where the interception of commercial communications leads to the diversion of substantial payments toward fraudulent accounts. While previous articles in this column addressed generic phishing and the burden of proof for gross negligence, the focus now shifts to the specificity of Business Email Compromise and the standard of the banker's professional diligence. The core of the issue lies in the delicate balance between payment automation based on the unique identifier (IBAN) and the protection obligation weighing on the beneficiary's bank. Through the reconstruction of a twin case starring Gaio Sventura, we will analyze how contributory negligence between a distracted employee and an inactive credit institution can determine the outcome of compensation claims. The story highlights the need for companies to implement robust cybersecurity protocols, not only to defend assets, but to prevent their own negligence from becoming an insurmountable defense in civil court.

Civil Liability for Man-in-the-Middle Scams in Corporate Payments

In brief

The article analyzes civil liability in Man-in-the-Middle (MITM) scams, starting from recent jurisprudential developments. The central focus is the coordination between Art. 1176 of the Civil Code, on the bank's professional diligence, and Art. 1227 of the Civil Code, on the victim company's contributory negligence. It delves into the obligation to verify the consistency between IBAN and account holder, moving beyond the rigid automation of digital payments in favor of greater protection for professional clients.

  1. The facts

    The case, as reported by outlets such as Altalex, belongs to a context of serial litigation that has reached a consolidation phase in the courts of merit. The typical dynamic involves a company awaiting an invoice from a regular supplier, which receives an apparently legitimate email communication announcing a change in banking details for the balance. In reality, a cybercriminal has inserted themselves into the email chain (Business Email Compromise), replacing the original IBAN with that of a so-called money mule. The company employee, without performing further telephone verification, orders the wire transfer. The ordering bank executes the operation based on the IBAN, and the receiving bank credits the funds to an account often opened with superficial identification procedures, allowing the scammer to withdraw the money immediately. The procedural stage of these cases is predominantly that of first instance and civil appeal, where companies sue institutions for failing to detect the obvious discrepancy between the beneficiary's name indicated in the transfer and the actual holder of the receiving bank account.

    1. Art. 1176, paragraph 2, of the Civil Code imposes a professional diligence on the bank superior to that of a reasonable person, obliging it to use technical tools suitable for preventing frauds detectable with ordinary industry expertise.
    2. Art. 24 of Legislative Decree no. 11/2010 establishes that the IBAN is the unique identifier for payment execution, but the rule does not exempt the bank from liability if the damage stems from intent or gross negligence in managing the security system.
    3. Art. 1227 of the Civil Code regulates the contributory negligence of the creditor, allowing the judge to reduce the compensation amount if the scammed company contributed to the damage by failing to monitor the security of its IT communications.
  2. What the case law says

    The case law of the Supreme Court has clarified that payment service providers must act as prudent bankers, which implies a protection obligation towards the client that goes beyond simple mechanical execution of orders. In particular, several courts of merit have established that, if there is a macroscopic divergence between the IBAN and the beneficiary's name, the receiving bank cannot remain inactive, as current technology easily allows for a consistency check (so-called cross-check). The prevailing orientation suggests that the bank is liable if it does not prove it adopted all security measures consistent with the state of the art to intercept anomalous operations. However, judges tend to almost always recognize contributory negligence on the part of the victim company, ranging between 30% and 50%, if the scam was facilitated by negligent password management or the failure to check obvious anomalies in the sender's email address (such as minor spelling errors in the domain).

  3. Analysis drafted and verified with edit.legal

    To verify the provisions cited in this article, we used edit.legal. Test our legal AI on official sources and apply it to your own matters.

    Try edit.legal AI
  4. What it teaches professionals

    1. It is essential to advise client companies to adopt double-verification protocols (by telephone or through encrypted channels) for every change in banking details received via email.
    2. In litigation, the lawyer must focus on proving the failure to implement the name-IBAN consistency check as a violation of the professional diligence of a prudent banker.
    3. It is necessary to pre-evaluate the impact of the employee's contributory negligence, preparing defensive strategies that demonstrate the sophistication of the cyberattack to reduce the company's share of liability.

References: Art. 1176 c.c.Art. 1227 c.c.D.Lgs. n. 11/2010Direttiva UE 2015/2366 (PSD2)

Avv. Federico Papa
Editorial oversight: Avv. Federico Papa·ICAMContent drafted with AI support and subject to editorial source checks. Despite these controls, inaccuracies may remain: reports and rectification requests are welcome. Report a correction

Frequently asked questions

Is the bank always obliged to refund a Man-in-the-Middle scam?

No, the refund is not automatic; it depends on proof that the bank did not act with the required professional diligence and that the user did not commit gross negligence.

What are the risks if an employee falls for a Business Email Compromise scam?

The company risks losing the paid amounts and a liability action against the director for failure to monitor cyber risks, plus a possible finding of contributory negligence in the lawsuit against the bank.

What is the statute of limitations for a compensation claim against the bank?

The action for contractual liability related to payment services generally lapses after ten years, but it is crucial to report the fraud immediately to limit damages.

Verified legal research and drafting with edit.legal

Legal research and drafting with citations checked against official databases. edit.legal is free to try, no credit card.

Try edit.legal for free